SYMBOLCOMMON_NAMEaka. SYNONYMS
win.voidstealer (Back to overview)

VoidStealer

VTCollection    

According to Gen Threat Labs, VoidStealer is a Malware-as-a-Service infostealer that targets browser credentials and is the first observed malware in the wild to employ a novel debugger-based Application-Bound Encryption bypass technique. It attaches to the browser process as a debugger and sets hardware breakpoints at specific code locations to extract the v20_master_key directly from browser memory during startup, without requiring privilege escalation or code injection. The technique is adapted from the open-source ElevationKatz project and specifically targets Chromium-based browsers such as Chrome and Edge. As a fallback, VoidStealer also implements a traditional process injection method to invoke the browser's internal decryption interface when the debugger approach is unavailable.

References
2026-03-19 ⋅ Gen ⋅ Vojtěch Krejsa
VoidStealer: Debugging Chrome to Steal Its Secrets
VoidStealer
Yara Rules
[TLP:WHITE] win_voidstealer_auto (20260917 | Detects win.voidstealer.)
rule win_voidstealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.voidstealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.voidstealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { f6d1 410fbec1 2a0d???????? 0fbec9 0fafc8 884c2450 8b442414 }
            // n = 7, score = 100
            //   f6d1                 | mov                 byte ptr [ebp - 9], dh
            //   410fbec1             | dec                 eax
            //   2a0d????????         |                     
            //   0fbec9               | lea                 ecx, [ebp - 9]
            //   0fafc8               | dec                 eax
            //   884c2450             | mov                 eax, edi
            //   8b442414             | dec                 eax

        $sequence_1 = { 8b0d???????? f7d1 8b05???????? 0528ffffff 8905???????? 8b442468 05b8000000 }
            // n = 7, score = 100
            //   8b0d????????         |                     
            //   f7d1                 | movsx               ecx, cx
            //   8b05????????         |                     
            //   0528ffffff           | imul                edx, ecx
            //   8905????????         |                     
            //   8b442468             | mov                 ebx, dword ptr [esp + 0x60]
            //   05b8000000           | sub                 bx, dx

        $sequence_2 = { eb24 4c8b45a8 b93b6f0000 410fbec0 6603c1 6689442448 488b442468 }
            // n = 7, score = 100
            //   eb24                 | mov                 edx, esp
            //   4c8b45a8             | jmp                 0x123b
            //   b93b6f0000           | inc                 esp
            //   410fbec0             | mov                 eax, edi
            //   6603c1               | inc                 ecx
            //   6689442448           | mov                 ebx, 1
            //   488b442468           | movzx               ecx, word ptr [esp + 0x48]

        $sequence_3 = { e8???????? 90 488d4d10 e8???????? 488d4df0 e8???????? 90 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   90                   | mov                 eax, ebp
            //   488d4d10             | dec                 eax
            //   e8????????           |                     
            //   488d4df0             | mov                 dword ptr [ebp - 0x18], eax
            //   e8????????           |                     
            //   90                   | dec                 eax

        $sequence_4 = { b808000000 66394520 0f85c2000000 0f57c0 0f114560 0f57c9 f30f7f4d70 }
            // n = 7, score = 100
            //   b808000000           | lea                 ecx, [ebp + 0x280]
            //   66394520             | nop                 
            //   0f85c2000000         | dec                 eax
            //   0f57c0               | lea                 ecx, [ebp + 0x1b8]
            //   0f114560             | nop                 
            //   0f57c9               | nop                 
            //   f30f7f4d70           | dec                 eax

        $sequence_5 = { eb50 0fb74c2444 66030d???????? 0fb7442444 6603c8 66894c2444 418bc3 }
            // n = 7, score = 100
            //   eb50                 | jmp                 0x6ba
            //   0fb74c2444           | inc                 ecx
            //   66030d????????       |                     
            //   0fb7442444           | movzx               eax, sp
            //   6603c8               | jne                 0x6b3
            //   66894c2444           | shl                 al, 4
            //   418bc3               | jmp                 0x6c5

        $sequence_6 = { c644246026 4889442460 b8b3000000 6689442460 8a05???????? b89d470000 6689442460 }
            // n = 7, score = 100
            //   c644246026           | dec                 eax
            //   4889442460           | mov                 dword ptr [esp + 0x30], eax
            //   b8b3000000           | mov                 byte ptr [esp + 0x30], 0xa7
            //   6689442460           | mov                 byte ptr [esp + 0x38], 0xda
            //   8a05????????         |                     
            //   b89d470000           | mov                 dword ptr [esp + 0x20], eax
            //   6689442460           | dec                 eax

        $sequence_7 = { 90 488d4f40 488d5340 0f57c0 0f1101 48897110 48897118 }
            // n = 7, score = 100
            //   90                   | dec                 esp
            //   488d4f40             | mov                 dword ptr [esi + 0x10], ebp
            //   488d5340             | dec                 eax
            //   0f57c0               | mov                 dword ptr [esi + 0x18], 0xf
            //   0f1101               | inc                 esp
            //   48897110             | mov                 byte ptr [esi], ch
            //   48897118             | mov                 dword ptr [ebp - 0x40], 1

        $sequence_8 = { 90 488d4d58 e8???????? 90 488d4d78 e8???????? 4403e6 }
            // n = 7, score = 100
            //   90                   | dec                 eax
            //   488d4d58             | test                eax, eax
            //   e8????????           |                     
            //   90                   | jne                 0x5cf
            //   488d4d78             | lea                 ecx, [eax + 4]
            //   e8????????           |                     
            //   4403e6               | movzx               edi, cx

        $sequence_9 = { f7d1 4c63c1 488b15???????? 48f7d2 0fbe442444 f7d0 4898 }
            // n = 7, score = 100
            //   f7d1                 | not                 ecx
            //   4c63c1               | xor                 ecx, dword ptr [esp + 0x5c]
            //   488b15????????       |                     
            //   48f7d2               | not                 eax
            //   0fbe442444           | add                 ecx, eax
            //   f7d0                 | movzx               eax, word ptr [esp + 0x54]
            //   4898                 | sub                 ecx, eax

    condition:
        7 of them and filesize < 52495360
}
Download all Yara Rules